top of page

Privacy Policy

Last updated:  20/01/2025

NATALIA ROMA GRZYB company with HQ in Wrocław (53-601) przy ul.Tęczowa 83F/25, NIP: 8942868292 

§ 1. Definitions

  1. Administrator (Us/We) – NATALIA ROMA GRZYB Natalia Grzyb, ul. Tęczowa 83F/25, 53-601 Wrocław, NIP (Tax ID): 8942868292, REGON: 388144445.

  2. Personal Data – all information about an identified or identifiable natural person through one or more specific factors determining physical, physiological, genetic, mental, economic, cultural, or social identity, including device IP, location data, internet identifier, and information collected through cookies and other similar technologies.

  3. Policy – this Privacy Policy.

  4. GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement such data, and repealing Directive 95/46/EC (General Data Protection Regulation).

  5. Service – the website operated by us at the address: nataliaromagrzyb.com/#oferta

  6. User (You) – any natural person visiting the Service or using one or more services or functionalities described in the Policy.

§ 2. Data Processing in Connection with the Use of the Service
In connection with your use of the Service, we collect your data to the extent necessary to provide specific services offered, as well as information about your activity in the Service. Detailed rules and purposes for processing personal data collected during your use of the Service are described below.

§ 3. Purposes and Legal Bases for Data Processing in the Service
3.1 Use of the Service
We process the personal data of all persons using the Service (including: first name, last name, email address, telephone number, NIP/Tax ID, IP address or other identifiers, and information collected through cookies or other similar technologies) who are not registered Users (i.e., persons without a profile in the Service) for the following purposes:
3.1.1. to provide services electronically in terms of sharing content collected in the Service with Users – in which case the legal basis for processing is the necessity of processing for the performance of a contract (Art. 6(1)(b) GDPR);
3.1.2. for analytical and statistical purposes – in which case the legal basis for processing is our legitimate interest (Art. 6(1)(f) GDPR), consisting of conducting analyses of User activity and preferences to improve functionalities and services provided;
3.1.3. for the purpose of potentially establishing and pursuing claims or defending against them – the legal basis for processing is our legitimate interest (Art. 6(1)(f) GDPR), consisting of protecting our rights;
3.1.4. for marketing purposes (ours and our partners), in particular related to presenting behavioral advertising – the rules for processing personal data for marketing purposes are described in the "MARKETING" section.

3.2. Your activity in the Service, including your personal data, is recorded in system logs. The information collected in the logs is processed primarily for purposes related to the provision of services. We also process them for technical and administrative purposes, for the needs of ensuring the security of the IT system and managing this system, as well as for analytical and statistical purposes – in this regard, the legal basis for processing is our legitimate interest (Art. 6(1)(f) GDPR).

3.3. Use of Paid Services in the Service
3.3.1 If you place an order (purchase of a product or service) in the Service, we will process your personal data for the following purposes:
3.3.1.1 to fulfill the placed order – the legal basis for processing is the necessity of processing for the performance of a contract (Art. 6(1)(b) GDPR); for data provided optionally, the legal basis for processing is consent (Art. 6(1)(a) GDPR);
3.3.1.2 to fulfill statutory obligations incumbent upon us, resulting in particular from tax and accounting regulations – the legal basis for processing is a legal obligation (Art. 6(1)(c) GDPR);
3.3.1.3 for analytical and statistical purposes – the legal basis for processing is our legitimate interest (Art. 6(1)(f) GDPR), consisting of conducting analyses of your activity in the Service and your purchasing preferences to improve the functionalities used;
3.3.1.4 for the purpose of potentially establishing and pursuing claims or defending against them – the legal basis for processing is our legitimate interest (Art. 6(1)(f) GDPR), consisting of protecting our rights.

3.4 Marketing
3.4.1. We process your personal data to carry out marketing activities, which may consist of:
3.4.1.1 displaying marketing content that is not tailored to your preferences (contextual advertising); displaying marketing content corresponding to your interests (behavioral advertising);
3.4.1.2 sending email notifications about interesting offers or content, which in some cases contain commercial information (newsletter service);
3.4.1.3 conducting other types of activities related to direct marketing of goods and services (sending commercial information by electronic means and telemarketing activities).
3.4.2 For the purpose of carrying out marketing activities, in some cases, we use profiling (if you give your consent). This means that through automated data processing, we evaluate selected factors regarding natural persons to analyze their behavior or create a forecast for the future.

3.5 Newsletter
3.5.1 We provide a newsletter service on the terms specified in the regulations, only if you provide us with your email address for this purpose. Providing data is required to provide the newsletter service, and failure to provide it results in the inability to send it.
3.5.2 Personal data collected for the newsletter are processed:
3.5.2.1 to provide the newsletter sending service – the legal basis for processing is the necessity of processing for the performance of a contract (Art. 6(1)(b) GDPR);
3.5.2.2 in the case of directing marketing content to you as part of the newsletter – the legal basis for processing, including profiling, is our legitimate interest (Art. 6(1)(f) GDPR) in connection with the expressed consent to receive the newsletter;
3.5.2.3 for analytical and statistical purposes – the legal basis for processing is our legitimate interest (Art. 6(1)(f) GDPR), consisting of conducting analyses of User activity in the Service to improve functionalities;
3.5.2.4 for the purpose of potentially establishing and pursuing claims or defending against them – the legal basis for processing is our legitimate interest (Art. 6(1)(f) GDPR).

3.6 Direct Marketing
Your Personal Data may also be used by us to direct marketing content to you via various channels, i.e., via email, MMS / SMS, or by telephone. We undertake such activities only if you have given your consent, which can be withdrawn at any time.

3.7 Social Networks
We process your personal data when you visit our profiles on social media (Facebook, YouTube, Instagram, Twitter). This data is processed exclusively in connection with maintaining the profile, including informing you about our activities and promoting various types of events, services, and products. The legal basis for processing personal data for this purpose is our legitimate interest (Art. 6(1)(f) GDPR), consisting of promoting our own brand.

3.8 Cookies and Similar Technology
Cookies are small text files installed on your device when you browse the Service. Cookies collect information that facilitates the use of the website – e.g., by remembering your visits to the Service and the actions you perform. Within the Service, we may use the following types of cookies:
3.8.1 "Service" Cookies
We use so-called service cookies primarily to provide you with services provided electronically and to improve the quality of these services. In connection with this, we and other entities providing analytical and statistical services to us use cookies by storing information or gaining access to information already stored on your telecommunications terminal equipment (computer, phone, tablet, etc.). Cookies used for this purpose include:

  • User input cookies (session ID) for the duration of the session;

  • Authentication cookies used for services requiring authentication for the duration of the session;

  • User-centric security cookies used to detect authentication abuses;

  • Multimedia player session cookies (e.g., flash player cookies) for the duration of the session;

  • User interface customization cookies (persistent cookies) for the duration of the session or slightly longer;

  • Cookies used to monitor website traffic, i.e., data analytics, including Google Analytics cookies (these are files used by Google to analyze how you use the Service, to create statistics and reports on the functioning of the Service). Google does not use the collected data to identify the User nor does it combine this information to enable identification. Detailed information about the scope and rules of data collection in connection with this service can be found at: Google Privacy Partners.

3.8.2 "Marketing" Cookies
We and our trusted partners also use cookies for marketing purposes, including in connection with directing behavioral advertising to you. For this purpose, we and our trusted partners store information or gain access to information already stored on your telecommunications terminal equipment. The use of cookies and personal data collected through them for marketing purposes, in particular regarding the promotion of services and goods of third parties, requires your consent, which can be withdrawn at any time.

3.8.3 Cookie Management
If you do not want to receive cookies, you can change your browser settings. We reserve that disabling cookies necessary for authentication, security, and maintaining user preferences may make it difficult to use the Service.
To manage cookie settings, select the web browser you use from the list below and follow the instructions: Edge, Internet Explorer, Chrome, Safari, Firefox, Opera.
Mobile devices: Android, Safari (iOS), Windows Phone.

3.9 Important Marketing Techniques
The purpose and scope of data collection and its further processing and use by service providers, as well as the possibility of contact and the User's rights in this regard, are described in the privacy policy of the service providers. We may use:

  • https://www.facebook.com/policy.php

  • https://policies.google.com/privacy?hl=pl&gl=ZZ
    We may use remarketing techniques that allow for matching advertising messages to your behavior in the Service, which may give the illusion that your personal data is being used for tracking; however, in practice, we do not transfer any of your personal data to advertising operators. The technological condition for such activities is the enabled support for cookies.
    We may use a solution that examines user behavior by creating heat maps and recording behavior in the Service. This information is anonymized before being sent to the service operator so that they do not know which natural person it concerns. In particular, entered passwords and other personal data are not subject to recording.

§ 4. Period of Personal Data Processing
The period for which we process your data depends on the type of service provided and the purpose of processing. As a rule, data is processed for the duration of the service provision or order fulfillment, until the withdrawal of the expressed consent, or the submission of an effective objection to data processing (in cases where the legal basis for data processing is our legitimate interest).
The data processing period may be extended if the processing is necessary to establish and pursue potential claims or defend against them, and after that time only if and to the extent required by law.
After the processing period expires, your data is irreversibly deleted or anonymized.

§ 5. Your Rights
In connection with the processing of your personal data, you have the following rights:

  • Right to information about the processing of personal data – on this basis, at your request, we will provide you with information about the processing of data, including primarily the purposes and legal bases for processing, the scope of the data held, the entities to which it is disclosed, and the planned date of data deletion;

  • Right to obtain a copy of the data – on this basis, at your request, we will provide you with a copy of the processed data regarding the person making the request;

  • Right to rectification – at your request, we are obliged to remove any inconsistencies or errors in processed personal data and supplement them if they are incomplete;

  • Right to erasure (right to be forgotten) – on this basis, you can demand the deletion of data whose processing is no longer necessary to achieve any of the purposes for which they were collected;

  • Right to restriction of processing – on this basis, at your request, we will cease performing operations on your personal data – with the exception of operations you have consented to – and their storage, in accordance with adopted retention rules or until the reasons for the restriction of processing cease;

  • Right to data portability – on this basis – to the extent that your data is processed in connection with a concluded contract or expressed consent – we will issue the data provided by you in a format that allows it to be read by a computer. You can also request that we send this data to another entity – provided that we have the appropriate technical capabilities;

  • Right to object to data processing for marketing purposes – you may object to the processing of personal data for marketing purposes at any time, without the need to justify such an objection;

  • Right to object to other purposes of data processing – you may object at any time to the processing of personal data that takes place on the basis of our legitimate interest (e.g., for analytical or statistical purposes or for reasons related to property protection); an objection in this regard should contain a justification;

  • Right to withdraw consent – if data is processed on the basis of your consent, you have the right to withdraw it at any time, which, however, does not affect the lawfulness of the processing carried out before the withdrawal;

  • Right to lodge a complaint – if you believe that the way we process your personal data violates the provisions of the GDPR or other provisions regarding the protection of personal data, you can file a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych).

§ 6. Data Recipients
Because we want to provide the best possible services for you, we will disclose your personal data to our trusted partners, including in particular providers responsible for operating IT systems, entities such as banks and payment operators, entities providing accounting services, couriers (in connection with order fulfillment), marketing agencies (in the scope of marketing services), and our affiliates.
Your personal data will be shared with other entities for their own purposes, including marketing purposes, only if you give your consent.

§ 7. Transfer of Data Outside the EEA
The level of personal data protection outside the European Economic Area (EEA) may differ from that provided by European law. For this reason, we will transfer your personal data outside the EEA only when necessary and with an adequate level of protection. You will be notified of this each time.

§ 8. Personal Data Security
Please be assured that we take all steps to ensure that your personal data is processed by us in a secure manner – ensuring primarily that only authorized persons have access to your data and only to the extent necessary for the tasks they perform.
We take all necessary actions to ensure that our subcontractors and other cooperating entities guarantee the application of appropriate security measures in every case where they process your personal data on our behalf.

§ 9. Contact Details
In all matters referred to in this policy, in particular related to the processing of your personal data, you can contact us via:

Sign up for my newsletter! I write irregularly, but to the point - only in Polish!

  • Instagram
  • LinkedIn
  • Facebook
  • arroba_edited

© 2025 Natalia Roma Grzyb. All rights reserved.

bottom of page